Resilient State Estimation for Grid Cyber-Physical Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial control systems connected to the Internet are increasingly vulnerable to cyber-attacks, which can disrupt operations and cause catastrophic damage by introducing false data into the control systems.
Innovation Solution
A system that includes a normal space data source, a situational awareness module with an abnormal data generation platform using a generative model, and a processor that determines whether received data signals are normal or abnormal, localizes anomalies, and generates state estimations for cyber-physical systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing failure and diagnostics technologies are used to protect industrial control systems, then some level of protection is provided, but the systems remain vulnerable to cyber-attacks that introduce false data
Solution Approach 1:
The system performs preliminary actions by generating abnormal data samples in advance using a generative model, training the classifier beforehand to recognize attack patterns. This allows the system to be prepared for cyber-attacks before they occur, enabling proactive detection and response rather than reactive protection.
Solution Approach 2:
The patent creates a copy of abnormal data patterns through the generative model that generates synthetic attack samples. This copied abnormal data is then used to train the classifier, allowing the system to learn and recognize attack characteristics without actually experiencing the attacks, thus protecting against harmful factors while maintaining system integrity.
2Measurement precision
If the system continuously monitors and analyzes data signals to detect anomalies, then detection accuracy improves, but computational resources and processing time increase
Solution Approach 1:
The classifier is trained in advance using generated abnormal data and normal data, creating a pre-computed decision model. During actual operation, the system only needs to classify new data signals using this pre-trained model, significantly reducing real-time processing requirements while maintaining high detection accuracy.
Solution Approach 2:
The system uses a computationally efficient classification approach that leverages pre-trained models and threshold-based decision making. This disposable-like approach uses simple, low-cost computational operations (comparisons against trained thresholds) rather than expensive complex analysis, enabling rapid anomaly detection with minimal processing overhead.
3Reliability
If the system generates and stores abnormal data samples for training, then the ability to detect attacks improves, but data storage requirements and system complexity increase
Solution Approach 1:
The generative model creates synthetic copies of abnormal data patterns from existing normal data by learning the underlying distributions. This allows the system to generate unlimited abnormal samples without storing actual attack data, reducing storage requirements while maintaining comprehensive training capability for attack detection.
Solution Approach 2:
The system transforms normal data into abnormal data samples by applying parameter transformations through the generative model. This allows the system to create diverse attack scenarios by varying parameters in the generated data rather than storing actual attack instances, simplifying the data management infrastructure while improving detection reliability.
Data Source
AI summary
According to some embodiments, a system, method and non-transitory computer-readable medium are provided to protect a cyber-physical system having a plurality of monitoring nodes comprising: a normal space data source storing, for each of the plurality of monitoring nodes, a series of normal monitoring node values over time that represent normal operation of the cyber-physical system; a situational awareness module including an abnormal data generation platform, wherein the abnormal data generation platform is operative to generate abnormal data to represent abnormal operation of the cyber-physical system using values in the normal space data source and a generative model; a memory for storing program instructions; and a situational awareness processor, coupled to the memory, and in communication with the situational awareness module and operative to execute the program instructions to: receive a data signal, wherein the received data signal is an aggregation of data signals received from one or more of the plurality of monitoring nodes, wherein the data signal includes at least one real-time stream of data source signal values that represent a current operation of the cyber-physical system; determine, via a trained classifier, whether the received data signal is a normal signal or an abnormal signal, wherein the trained classifier is trained with the generated abnormal data and normal data; localize an origin of an anomaly when it is determined the received data signal is the abnormal signal; receive the determination and localization at a resilient estimator module; execute the resilient estimator module to generate a state estimation for the cyber-physical system Numerous other aspects are provided.


